diff --git a/README.md b/README.md index 95cd92bd..0ea221ea 100644 --- a/README.md +++ b/README.md @@ -23,16 +23,17 @@ First-of-its-kind patent-pending technology that automatically correlates outbou 2. In the workflow logs, you will see a link to security insights and recommendations.

- Link in build log + Link in build log

3. Click on the link ([example link](https://app.stepsecurity.io/github/jauderho/dockerfiles/actions/runs/1736506434)). You will see outbound traffic made by each step.

- Insights from harden-runner + Insights from harden-runner

+ Below the insights, you will see the recommended policy.

- Policy recommended by harden-runner + Policy recommended by harden-runner

4. Add the recommended outbound endpoints to your workflow file, and only traffic to these endpoints will be allowed.